Papers
Topics
Authors
Recent
Search
2000 character limit reached

Berlekamp–Massey–Sakata Algorithm

Updated 12 July 2026
  • Berlekamp–Massey–Sakata algorithm is a multidimensional generalization of the classical Berlekamp–Massey algorithm that computes Gröbner bases for error-locator ideals in algebraic codes.
  • It methodically updates polynomial candidates via discrepancies and shifts, leveraging recurrence relations to construct a complete Gröbner basis from syndrome arrays.
  • The algorithm is widely applied in decoding one-point, Hermitian, Reed–Muller, and affine variety codes, optimizing redundancy by matching error correction capabilities with the code structure.

The Berlekamp–Massey–Sakata algorithm is a multidimensional generalization of the classical Berlekamp–Massey algorithm. Introduced by Sakata, it is designed for decoding algebraic-geometry codes, especially one-point algebraic-geometry codes such as Hermitian codes, and it computes a Gröbner basis of the ideal of relations of a multidimensional linear recurrent sequence (Berthomieu et al., 2017). In coding-theoretic terms, it converts multidimensional syndrome data into locator polynomials; in algebraic terms, it constructs a finite Gröbner basis for a zero-dimensional ideal whose staircase encodes the recurrence structure of the sequence and, in decoding applications, the error support [0609162].

1. Multidimensional recurrences and the ideal of relations

A standard formal setting fixes a field KK and a multidimensional sequence

u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).

With multi-index notation x=(x1,…,xn)x=(x_1,\dots,x_n) and xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}, a linear recurrence relation for uu is given by a polynomial

f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]

such that

∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.

Using the bracket notation

[f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},

the polynomial ff is a relation for uu exactly when u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).0 for all u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).1 (Berthomieu et al., 2017).

The ideal of relations is

u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).2

A sequence is called linear recurrent when u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).3 is zero-dimensional. In that case there is a finite staircase u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).4 such that every monomial outside u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).5 lies in u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).6, and from finitely many initial values u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).7 and finitely many relations one can compute all terms u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).8 (Berthomieu et al., 2017). This staircase is the canonical monomial basis of the quotient u=(ui)i∈Nn,i=(i1,…,in).u = (u_i)_{i\in\mathbb{N}^n},\qquad i=(i_1,\dots,i_n).9, and its border is the natural location of the leading monomials of a Gröbner basis.

This algebraic formulation is the common core of several domains. In coding theory the sequence is a syndrome array and the ideal of relations is an error-locator ideal. In sparse interpolation and polynomial system solving it is a recurrence ideal or multi-Hankel kernel. The BMS algorithm is the standard procedure that computes this ideal by exploiting the recurrence constraints monomial by monomial (Mourrain, 2017).

2. Algorithmic structure: discrepancies, fail, shift, and staircase growth

The non-adaptive BMS algorithm fixes a monomial ordering x=(x1,…,xn)x=(x_1,\dots,x_n)0 that is a weight order, enumerates monomials x=(x1,…,xn)x=(x_1,\dots,x_n)1 in increasing order, tests current candidate relations up to x=(x1,…,xn)x=(x_1,\dots,x_n)2, computes discrepancies, and updates them via linear combinations as in the classical Berlekamp–Massey algorithm (Berthomieu et al., 2017). Its one-dimensional specialization behaves exactly like Berlekamp–Massey.

A polynomial x=(x1,…,xn)x=(x_1,\dots,x_n)3 is valid up to x=(x1,…,xn)x=(x_1,\dots,x_n)4 if

x=(x1,…,xn)x=(x_1,\dots,x_n)5

If x=(x1,…,xn)x=(x_1,\dots,x_n)6 is valid for all smaller shifts but fails at x=(x1,…,xn)x=(x_1,\dots,x_n)7, then

x=(x1,…,xn)x=(x_1,\dots,x_n)8

These notions generalize discrepancy location and span from the univariate case. A central update rule states that if two relations x=(x1,…,xn)x=(x_1,\dots,x_n)9 fail with the same shift

xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}0

and

xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}1

then

xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}2

has strictly larger shift. This is the multidimensional Berlekamp step (Berthomieu et al., 2017).

For each current bound xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}3, the set

xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}4

contains the relations valid up to xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}5. The corresponding staircase is

xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}6

where xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}7 is a truncated Gröbner basis of xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}8. As xi=x1i1⋯xninx^i=x_1^{i_1}\cdots x_n^{i_n}9 increases, the sets uu0 decrease and the staircases uu1 increase. For a linear recurrent sequence with true staircase uu2, one has uu3 for all uu4, where uu5. If uu6 is a minimal Gröbner basis of uu7 and uu8, then for

uu9

BMS returns f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]0 (Berthomieu et al., 2017).

A complementary polynomial-division interpretation replaces discrepancy tests by conditions on a mirror of the truncated generating series. In that view, BMS is revisited through multivariate polynomial divisions modulo a monomial ideal, and an adaptive variant achieves complexity depending only on the output Gröbner basis (Berthomieu et al., 2021).

3. One-point codes, order domains, and the generalized key equation

In one-point algebraic-geometry coding, the ambient object is a smooth irreducible projective curve f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]1 over f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]2 with a unique point f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]3 at infinity. For distinct rational points f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]4 away from f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]5, and f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]6 satisfying

f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]7

the one-point code is

f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]8

with dual

f=∑kαkxk∈K[x1,…,xn]f = \sum_k \alpha_k x^k \in K[x_1,\dots,x_n]9

(Andriamifidisoa et al., 2019).

The syndrome array is the generalized transform of the error vector: ∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.0 The associated error-locator ideal is

∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.1

and this ideal coincides with the vanishing ideal of the error support: ∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.2 Hence the syndrome array is a linear recurring sequence, and BMS constructs a Gröbner basis of ∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.3 from partial syndrome information (Andriamifidisoa et al., 2019).

The same framework can be phrased in Oberst’s language of dynamical systems. If ∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.4 is a column of Gröbner basis elements for ∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.5, then

∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.6

is a dynamical system, and the syndrome array is the unique solution of the Cauchy-type homogeneous equations

∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.7

Within this interpretation, the aim of BMS in the decoding process being the determination of the syndrome array, the algorithm solves the Cauchy’s homogeneous equations with respect to a dynamical system (Andriamifidisoa et al., 2019).

A parallel line of generalization places BMS inside order-domain theory. For evaluation codes defined by arbitrary subsets of monomials, order domains provide monomial subsets that can be chosen to optimize decoding performance using the Berlekamp-Massey-Sakata algorithm with majority voting, and for the families considered the dual codes are also defined by monomials [0609159]. In the one-point setting, the classical Reed–Solomon key equation, the Berlekamp–Massey algorithm, the Forney formula, and Horiguchi’s formula all generalize in a natural way to one-point codes, and the resulting algorithm is based on Kötter’s adaptation of Sakata’s algorithm (O'Sullivan et al., 2021).

4. Hermitian, Reed–Muller, and affine variety code applications

For Hermitian and related one-point codes, BMS is not only a decoder but also a design tool. Analysis of the Berlekamp-Massey-Sakata algorithm for decoding one-point codes leads to two methods for improving code rate. One method, due to Feng and Rao, removes parity checks that may be recovered by their majority voting algorithm. The second method is to design the code to correct only those error vectors of a given weight that are also geometrically generic. Formulae are given for the redundancies of Hermitian codes optimized with respect to these criteria as well as the formula for the order bound on the minimum distance; these results proceed from an analysis of numerical semigroups generated by two consecutive integers, and the formula for the redundancy of optimal Hermitian codes correcting a given number of errors answers an open question stated by Pellikaan and Torres in 1999 [0609162].

A closely related optimization occurs for Reed–Muller-type evaluation codes. Variations of Reed-Muller codes yield improvements to the rate for a prescribed decoding performance under the Berlekamp-Massey-Sakata algorithm with majority voting, and explicit formulas for the redundancies of the new codes are given [0609160]. In both Hermitian and Reed–Muller settings, the recurring theme is that redundancy can be matched to the actual correction capability delivered by BMS and majority voting rather than to a purely distance-based design criterion.

For affine variety codes, BMS is paired with multidimensional discrete Fourier transforms. An efficient procedure for error-value calculations based on fast discrete Fourier transforms in conjunction with Berlekamp-Massey-Sakata algorithm for a class of affine variety codes is proposed; the procedure is achieved by multidimensional DFT and linear recurrence relations from Gröbner basis and is applied to erasure-and-error decoding and systematic encoding (Matsui, 2012). In that framework, BMS performs error-location by computing a Gröbner basis of the error-locator ideal, while the DFT machinery computes error values. The total complexity of the decoding algorithm is bounded by

∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.8

which improves the complexity of error-value calculations compared with solving systems of linear equations from error correcting pairs in many cases (Matsui, 2012).

5. Comparisons, reformulations, and computational variants

A recurrent misconception is that BMS and Scalar-FGLM are merely different implementations of the same strategy. A detailed comparison shows that this is not the case. BMS and Scalar-FGLM both compute the ideal of relations of a multi-dimensional linear recurrent sequence, but their behaviors differ, and it is not possible to tweak one of the algorithms in order to mimic exactly the behavior of the other (Berthomieu et al., 2017). In particular, BMS always returns relations whose leading monomials cover the entire border of the staircase, whereas Scalar-FGLM may leave the staircase open and can produce a positive-dimensional ideal when the bound is too small. For a total-degree order, the cited complexity bound for BMS is

∀i∈Nn,∑kαk ui+k=0.\forall i\in\mathbb{N}^n,\quad \sum_k \alpha_k\,u_{i+k}=0.9

field operations (Berthomieu et al., 2017).

Several later algorithms reinterpret or extend BMS. A polynomial-division-based approach computes the Gröbner basis of the ideal of relations of a sequence based solely on multivariate polynomial arithmetic; it revisits the Berlekamp-Massey-Sakata algorithm through the use of polynomial divisions and revises Scalar-FGLM without linear algebra operations (Berthomieu et al., 2021). Its adaptive variant has complexity and sequence-query counts depending only on the output Gröbner basis.

A border-basis viewpoint identifies multi-index sequences, multivariate formal power series, and linear functionals on polynomial rings, and describes recurrence relations as the kernel [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},0 of the Hankel operator [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},1. In that setting, the quotient algebra [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},2 is Artinian Gorenstein when [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},3 has finite rank, and the algorithm computes a border basis, pairwise orthogonal bases, and multiplication tables. It is presented as an extension of Berlekamp-Massey-Sakata with arithmetic complexity

[f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},4

compared with about [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},5 for classical BMS in the same notation (Mourrain, 2017).

BMS also appears outside coding theory. In sparse FGLM algorithms for changing Gröbner basis orderings from DRL to LEX, the general-case method is characterized by the Berlekamp-Massey-Sakata algorithm from coding theory to handle the multi-dimensional linearly recurring relations (Faugère et al., 2013). Here the multidimensional sequence is

[f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},6

and BMS is used to recover, with high probability, the target Gröbner basis under the new ordering (Faugère et al., 2013).

6. Inverse-free decoding, missing syndromes, and incomplete tables

Hardware and implementation issues have generated a substantial subliterature. An inverse-free Berlekamp-Massey-Sakata algorithm eliminates division-calculations of finite fields from the BMS algorithm. This inverse-free algorithm provides full performance in correcting generic errors, which includes most errors, and can decode codes on algebraic curves without the determination of unknown syndromes. The same work proposes three different kinds of architectures, represents the control operation of shift-registers and switches at each clock-timing with numerical simulations, and estimates the performance in comparison of the total running time and the numbers of multipliers and shift-registers in three architectures with those of the conventional ones for codes on algebraic curves (0705.0286).

Recent work addresses a different implementation bottleneck: missing syndromes. One study investigates the problem of finding those missing syndrome values that are needed to implement the Berlekamp-Massey-Sakata algorithm as the Feng-Rao Majority Voting for algebraic geometric codes, and applies the resulting criteria to syndrome correction in abelian codes (Bernal et al., 18 Sep 2025). A companion development extends results about the implementation of the Berlekamp-Massey-Sakata algorithm on data tables having a number of unknown values (Bernal et al., 22 Sep 2025).

The geometric language used there is that of hyperbolic sets. For amplitude [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},7, the hyperbolic set is

[f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},8

For [f]u:=∑kαkuk,[xif]u:=∑kαkui+k,[f]_u := \sum_k \alpha_k u_k,\qquad [x^i f]_u := \sum_k \alpha_k u_{i+k},9, hyperbolic tables with known entries on ff0 are sufficient for BMS-based reconstruction in the low-weight regime (Bernal et al., 22 Sep 2025). This fits the earlier result that, for hyperbolic-like abelian codes, one can find a set of indexes of the syndrome table such that no other syndrome contributes to implement the BMSa and, moreover, any of them may be ignored a priori; implementation on those indexes is sufficient to get the Gröbner basis and is also a termination criterion, yielding decoding up to 4 errors (Bernal et al., 2020).

These developments underscore a persistent feature of the algorithm: BMS is simultaneously a recurrence-finding procedure, a Gröbner basis algorithm, a decoder for one-point and abelian codes, and a framework whose practical performance depends strongly on monomial order, syndrome availability, and the geometry of the index set on which the multidimensional sequence is observed.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Berlekamp-Massey-Sakata Algorithm.